SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5362

Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS…

MEDIUM 4.4EPSS 0.29%

Does this matter?

Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.

Description

Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.

CVSS 3.1
4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS
0.29% probability · 22th percentile
CISA KEV
Not listed
Weakness
CWE-285, CWE-862
Affected
dell/chengming 3967 firmware · dell/chengming 3977 firmware · dell/chengming 3980 firmware · dell/chengming 3988 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g3 15 3500 firmware · dell/g3 15 3590 firmware · dell/g3 3579 firmware · dell/g3 3779 firmware · dell/g5 15 5500 firmware · dell/g5 15 5590 firmware · dell/g5 5587 firmware · dell/g7 15 7590 firmware · dell/g7 17 7790 firmware · dell/g7 7588 firmware · dell/embedded box pc 5000 firmware · dell/g5 5090 firmware · dell/inspiron 11 2-in-1 3153 firmware · dell/inspiron 11 2-in-1 3158 firmware · +40 more
Source
security_alert@emc.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.